Law · Privacy · California

CCPA CPRA compliance: rights, the 2026 regulations and audits

CCPA CPRA compliance means meeting the California Consumer Privacy Act as amended by the California Privacy Rights Act, enforced by the CPPA and the Attorney General. New CPPA regulations took effect on 1 January 2026, adding privacy risk assessments, rules for automated decision-making and annual cybersecurity audits from 2028.

Key takeaways

What you need to know about CCPA / CPRA

Thresholds decide scopeRevenue, data volume or data-selling share brings you in.
Opt-out signals countBrowser signals such as Global Privacy Control must be honoured.
New 2026 dutiesRisk assessments apply now; audits and submissions follow.
Security is auditedIndependent cybersecurity audits arrive from 2028.
Breach lawsuitsConsumers can sue after breaches caused by weak security.

Who must comply with the CCPA?

For-profit businesses doing business in California that meet one of the thresholds.

Large businessesAbove the inflation-adjusted revenue threshold.
Data-heavy businessesBuying, selling or sharing data of 100,000+ consumers or households.
Data brokersEarning half their revenue from selling or sharing data.
Service providersThrough contracts with businesses.
Out-of-state companiesDoing business in California.

QULDEX helps here first: the readiness check shows where you stand before you commit budget.

What the law requires

What does the CCPA require?

The CCPA requires covered businesses to give notice at collection, honour rights to know, delete, correct, opt out and limit, keep contracts with service providers, maintain reasonable security and, under the 2026 regulations, assess risk, audit cybersecurity and govern ADMT.

Notice Inform

Notice at collection

What, why and how long.

In QULDEX: Notice versions
Rights Respond

Consumer rights

Know, delete, correct, opt out, limit.

In QULDEX: Request log with deadlines
Opt-out Honour

Sale and sharing opt-outs

Including Global Privacy Control.

In QULDEX: Signal tests
2026 regs Assess

Risk assessments and ADMT

Significant-risk processing.

In QULDEX: Assessment workflow
Audits Audit

Cybersecurity audits

From 2028 by revenue.

In QULDEX: Audit workspace
Security Protect

Reasonable security

Breach lawsuits if not.

In QULDEX: Security evidence
Section explorer

Which CCPA sections and rules matter most?

These 15 sections and regulations carry the obligations most businesses work on. Select any one to see what it requires, typical evidence and the matching GDPR or security reference.

2020CCPA in force
2023CPRA amendments
Jan 2026new regulations
Apr 2028first audits due

Showing up to 6 per group. Search, filter, or open a group to see all 15.

Scope 2

  1. 1798.140(d)Who is a business

    For-profit entities doing business in California that meet a revenue threshold (adjusted for inflation), buy, sell or share data of 100,000+ consumers or households, or earn half their revenue from selling or sharing personal information.

    In QULDEXThresholds are recorded with the figures used.

    Typical evidence
    Applicability assessment

  2. 1798.140(v)Personal and sensitive personal information

    Personal information is broad; sensitive personal information includes government IDs, precise geolocation, health, biometrics and account log-ins.

    In QULDEXSensitive data is tagged in the data map.

    Typical evidence
    Data map

Consumer rights 6

  1. 1798.100Right to know and notice at collection

    Tell consumers at or before collection what you collect, why and for how long.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.

    Typical evidence
    Notice at collection
    Maps to
    GDPR Art. 13

  2. 1798.105Right to delete

    Delete personal information on request, with listed exceptions, and tell service providers to delete too.

    In QULDEXRequests are logged with 45-day deadlines.

    Typical evidence
    Request log
    Maps to
    GDPR Art. 17

  3. 1798.106Right to correct

    Correct inaccurate personal information on request.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.

    Maps to
    GDPR Art. 16

  4. 1798.120Right to opt out of sale or sharing

    Offer "Do Not Sell or Share My Personal Information" and honour opt-out preference signals such as Global Privacy Control.

    In QULDEXOpt-out signals are tested as a control.

    Typical evidence
    Opt-out evidence

  5. 1798.121Right to limit sensitive data use

    Let consumers limit the use of sensitive personal information.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.

    Typical evidence
    Limit link evidence

  6. 1798.125No discrimination

    Do not discriminate against consumers for exercising their rights.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.

2026 regulations 3

  1. Cyber auditAnnual cybersecurity auditsNew in 2026 regulations

    Businesses whose processing presents significant risk complete independent cybersecurity audits; first certifications are due from 1 April 2028 to 2030, by revenue.

    In QULDEXAudit scope and evidence sit in the audit workspace.

    Typical evidence
    Cybersecurity audit report
    Maps to
    ISO 27001SOC 2

  2. Risk assessmentPrivacy risk assessmentsNew in 2026 regulations

    Assess processing that presents significant risk, such as selling or sharing data or processing sensitive data; compliance from 1 January 2026, submissions from April 2028.

    In QULDEXRisk assessments run with sign-off and submission records.

    Typical evidence
    Risk assessments
    Maps to
    GDPR Art. 35

  3. ADMTAutomated decision-making technologyNew in 2026 regulations

    Notice, opt-out and access rights where ADMT is used for significant decisions, from 2027.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.

    Typical evidence
    ADMT notices
    Maps to
    EU AI Act

Obligations and enforcement 4

  1. 1798.100(d)Contracts with service providers and contractors

    Contracts must limit use of personal information and require compliance.

    In QULDEXEach service provider is linked to its contract terms.

    Typical evidence
    Contracts
    Maps to
    GDPR Art. 28

  2. 1798.100(e)Reasonable security

    Implement reasonable security procedures and practices appropriate to the data.

    In QULDEXSecurity controls are reused from ISO 27001 or SOC 2.

    Typical evidence
    Security evidence
    Maps to
    ISO 27001

  3. 1798.150Private right of action for breaches

    Consumers can sue for data breaches caused by a failure to maintain reasonable security.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.

  4. 1798.155Administrative fines

    Fines per violation, higher for intentional violations or those involving minors, adjusted for inflation; enforced by the CPPA and the Attorney General.

    In QULDEXQULDEX gives this obligation an owner, evidence requests and a review date, and maps it to GDPR and ISO 27701.

Section numbers follow the California Civil Code; regulation summaries follow the CPPA regulations approved in September 2025. Summaries are QULDEX paraphrases, not legal advice.

Compliance path

How do you comply with the CCPA and the 2026 regulations?

Confirm you are covered, map personal and sensitive data, fix notices and rights handling, then add risk assessments now and prepare for audits and ADMT rules. Most businesses need 3 to 6 months for the core and plan the audit work into 2027.

  1. Confirm the thresholds

    Revenue, data volume and selling or sharing share.

  2. Map personal and sensitive data

    Sources, purposes, retention, sharing and service providers.

  3. Notices, rights and opt-outs

    Notice at collection, request handling and Global Privacy Control.

  4. Risk assessments

    Assess significant-risk processing from 1 January 2026.

  5. Prepare the cybersecurity audit

    Scope, evidence and an independent auditor before your due date.

  6. Keep it current

    2027ADMT rules apply
    Apr 2028First audit certifications and risk assessment submissions
    YearlyAudits continue

Dates follow the CPPA regulations approved in September 2025. Durations are QULDEX planning ranges.

Records to keep

Which records does CCPA compliance need?

The CPPA and auditors will ask for these.

RecordSectionWhere it lives in QULDEX
Applicability assessment1798.140(d)Risk register
Data map with sensitive data1798.140(v)Risk register
Notice at collection and privacy policy1798.100Policy library
Consumer request log1798.105–1798.121Evidence vault
Opt-out signal test evidence1798.120Evidence vault
Service provider contracts1798.100(d)Vendor register
Privacy risk assessments2026 regulationsAudit workspace
Cybersecurity audit report and certification2026 regulationsAudit workspace

Record names are QULDEX recommendations.

Time and cost

How long does CCPA compliance take and what drives the effort?

The core programme typically takes 3 to 6 months; the cybersecurity audit adds 3 to 6 months of preparation before its due date. Data selling or sharing, sensitive data and ad-tech drive the effort.

Where the time goes

Thresholds and data map4–8 wk
Notices and rights1–2 mo
Opt-out signals3–6 wk
Risk assessments1–2 mo
Audit preparation3–6 mo

Bars show the upper end of each range on one scale (6 months = full width).

What changes the effort

  • Selling or sharing: adds opt-outs and risk assessments
  • Ad-tech and cookies: opt-out signals must reach every tag
  • Sensitive data: limit rights and assessments
  • Revenue band: sets the audit due date
  • Existing SOC 2 or ISO 27001: supports the cybersecurity audit
Readiness check · 2 minutes

How ready are you for the CCPA?

Check these eight things first. Nothing you enter leaves this page.

ScopeHave you confirmed which thresholds you meet?
Data mapDo you know where personal and sensitive data is?
NoticeDo you give notice at or before collection?
RightsCan you answer know, delete and correct requests within 45 days?
Opt-outDo you honour Global Privacy Control signals?
ContractsDo service provider contracts include CCPA terms?
RiskHave you assessed significant-risk processing?
AuditDo you know your cybersecurity audit due date?
Crosswalk

How the CCPA maps to GDPR, ISO 27701 and SOC 2

The CCPA is opt-out based where GDPR is consent based, but rights handling, risk assessments and security evidence overlap heavily.

CCPA vs GDPR at a glance

CCPA / CPRAGDPR
ModelNotice and opt-out (opt-in for minors)Lawful basis, often consent
ScopeBusinesses meeting thresholdsAny controller or processor in scope
AssessmentsRisk assessments under 2026 regulationsDPIAs for high risk
Security auditsIndependent cybersecurity audits from 2028No audit mandate
EnforcementCPPA, Attorney General, private action for breachesSupervisory authorities
In QULDEXQULDEX maps each process to both laws, so one privacy programme serves California and the EU.

Privacy crosswalk

CCPA / CPRAGDPRISO 27701:2025SOC 2Shared evidence
1798.100 NoticeArt. 13–14NoticesP1Notices
1798.105 DeleteArt. 17ErasureP4Request log
1798.120 Opt-outArt. 21ObjectionP2Opt-out evidence
1798.100(d) ContractsArt. 28Processor contractsCC9.2Contracts
Reasonable securityArt. 32Security for PIICC6–CC8Security evidence
Risk assessmentsArt. 35Impact assessmentCC3.2Assessments
Cybersecurity audit——SOC 2 reportAudit report

Indicative mapping for planning, not legal advice.

Where QULDEX fits

How QULDEX runs CCPA compliance from data map to cybersecurity audit

QULDEX is CCPA compliance and audit management software built from EGV Group's audit delivery, used by businesses, their privacy teams and the independent cybersecurity auditors the 2026 regulations require. Pick your role to see who does what.

For businesses meeting the CCPA thresholds.

  1. ScopeConfirm thresholdsApplicability record
  2. MapMap dataData map with sensitive data
  3. RightsAnswer requestsRequest log with deadlines
  4. AssessRun risk assessmentsAssessment workflow
  5. SecurityProve reasonable securityControls mapped to ISO 27001 and SOC 2
  6. CertifyCertify the auditCertification pack
Without one systemWith QULDEX
Opt-out links but no signal handlingGlobal Privacy Control tested as a control
Requests answered by emailA request log with 45-day deadlines
Audit due date unknownAudit planned against the revenue band
Privacy and security run separatelyOne programme mapped to both
10+years of audit delivery500+audits deliveredBoth sidesof the audit on one platformRBACand a full audit trail on every action
FAQ

CCPA / CPRA questions people ask

Who must comply with the CCPA?

For-profit businesses doing business in California that exceed the inflation-adjusted revenue threshold, buy, sell or share personal information of 100,000 or more consumers or households, or earn at least half their revenue from selling or sharing personal information.

What did the 2025 CCPA regulations add?

Regulations approved in September 2025 and effective 1 January 2026 add privacy risk assessments, rules for automated decision-making technology (from 2027) and annual cybersecurity audits (certifications from 2028).

When are CCPA cybersecurity audits due?

Certifications are due by 1 April 2028 for businesses with over $100 million in revenue, 1 April 2029 for $50–100 million, and 1 April 2030 for those under $50 million.

What are the CCPA penalties?

Administrative fines per violation, higher for intentional violations or those involving minors, adjusted for inflation each year, plus statutory damages in consumer lawsuits after certain data breaches.

What rights do California consumers have?

To know, delete and correct their personal information, to opt out of its sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for using these rights.

Sources

References

  1. California Civil Code 1798.100 et seq. (CCPA as amended by CPRA). leginfo.legislature.ca.gov
  2. CPPA regulations on cybersecurity audits, risk assessments and ADMT, approved 23 Sep 2025. cppa.ca.gov
  3. California Attorney General CCPA page. oag.ca.gov
  4. Skadden, California finalizes CPPA regulations, Oct 2025. skadden.com

Reviewed by

Abhishek Yadav

Lead Auditor · QULDEX

Reviewed this page against the CCPA as amended by the CPRA and the CPPA regulations effective 1 January 2026.

Page history
  • : Page first built: section explorer with the 2026 regulations, audit timeline and readiness check

Plan your CCPA cybersecurity audit now

Answer a short readiness check and get a gap summary by area. No sales call needed to see the result.

Schedule
Book a Demo